Description
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution via module injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a malicious project to define a bogus golang.org/fips140 module and, by controlling a GOMODPROXY, serve an arbitrary module that satisfies the toolchain’s trust checks. The build process unpacks the trusted ziphash for the bundled golang.org/fips140 module and constructs its entry in the GOMODCACHE, effectively bypassing checksum verification. An attacker can therefore inject arbitrary code that runs during a Go build, compromising confidentiality, integrity, and potentially availability of the built binary.

Affected Systems

Go toolchain cmd/go is affected. No specific version information is provided; the issue applies to any installation of the Go toolchain that accepts modules from a user‑defined GOMODPROXY and verifies their checksum packages.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the impact is high: an attacker can ship code that executes during compilation. The likely attack vector is an environment where the build user selects or is directed to a malicious GOMODPROXY, allowing the attacker to host the forged golang.org/fips140 module. Without an official CVSS score, its severity remains undetermined, yet the potential for arbitrary code execution warrants a high risk assessment.

Generated by OpenCVE AI on October 9, 2026 at 00:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Go release where the checksum bypass has been fixed.
  • Configure Go to use a trusted GOSUMDB and restrict modules from untrusted proxies by setting GONOPROXY or GONOSUMDB for golang.org/fips140.
  • Verify the integrity of modules manually by inspecting checksum files or using tools that enforce strict checksum validation.

Generated by OpenCVE AI on October 9, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
Description Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
Title Checksum bypass for golang.org/fips140 in cmd/go
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published:

Updated: 2026-10-08T22:53:57.787Z

Reserved: 2026-09-21T16:43:04.757Z

Link: CVE-2026-94444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T23:17:05.050

Modified: 2026-10-08T23:17:05.050

Link: CVE-2026-94444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T00:30:17Z

Weaknesses

No weakness.